Please do not report security vulnerabilities through public GitHub issues.
Instead, open a GitHub Security Advisory so it can be reviewed privately.
Include as much detail as possible: steps to reproduce, potential impact, and any suggested fixes.
You can expect a response within 7 days.